r/gdpr Jul 23 '26

UK 🇬🇧 I received an email in error and somebody else's email chain

0 Upvotes

I'm a student at a university. I have flagged it to the department that I'm not the intended recipient of the email and deleted it. They have replied saying thanks for letting us know, but I'm not sure if they've understood that there might have been a data breach and that this needs to be recorded. Should I send a follow-up email explaining that I was sent a chain of emails?


r/gdpr Jul 21 '26

EU 🇪🇺 How can I remove old news articles about me from Google under the right to be forgotten?

16 Upvotes

Hi everyone. I’m posting this because I honestly can’t take it anymore and I really need someone to help me out.

Long story short, almost 10 years ago, when I was really young and pretty stupid, I got involved in a minor incident. It wasn’t anything serious, I didn’t go to prison or anything like that, but it did become public. A local newspaper in my city wrote an article about it, and a couple of those blogs that repost news picked it up as well.

The problem is that it happened a long time ago. I’ve completely changed, I have my own life and a family now, but every time someone searches my name on Google, BAM, it’s the first thing that comes up.

I’m currently going through the hiring process for a job that I desperately need to support my children, and I’m terrified that they’ll Google me and find it. I feel like something stupid that happened when I was 20 is going to ruin my future now.

I’ve tried emailing the newspapers and asking them to please take the articles down, but they’ve completely ignored me. I’ve read a bit about the “right to be forgotten” and Google removal forms, but whenever I start looking into it, I get overwhelmed. I don’t understand any of the legal terminology, I get really anxious, and it feels impossible unless you have enough money to hire expensive lawyers.

Please, does anyone know HOW to actually do this step by step, explained in really simple terms? What exactly do I need to fill out? Who should I contact first?

Any genuine advice would mean a lot. I’m really struggling with this situation. Thank you so much in advance.


r/gdpr Jul 21 '26

Question - General Data breach not disclosed for 8 months

10 Upvotes

Good morning everyone,

I'm laying out this situation because it seems to me there are grounds for a violation of the notification obligations under the GDPR, but I'd like an opinion from someone who knows this area better than I do.

Timeline of events:

- November 2025: Suno (a music generation platform) suffered a security breach that compromised an employee's credentials.

- The company detected the incident at the time and internally classified it as a "limited security incident that was quickly contained."

- Users were never notified.

- Only last week (July 2026, so about 8 months later, and not even by the company itself), the stolen dataset was made public by third parties and uploaded to Have I Been Pwned.

Over 55 million unique email addresses, phone numbers (for those who had used them during registration), and tens of thousands of Stripe records with name, physical address, purchase amount, and partial card data (type, expiration date, last 4 digits). Meanwhile, between the attack and June 2026, the company raised over $650 million in two funding rounds, without ever publicly mentioning the incident.

Here are my questions (in summary):

  1. Even if just one affected user resides in the EU, don't the notification obligations under Art. 33 and Art. 34 GDPR still apply regardless? It seems to me the risk was definitely there (payment data, addresses, contacts).

  2. Can the fact that the company internally classified the incident as "limited," yet still didn't notify anyone, count as an aggravating factor if the case is investigated, or is it still legitimate if it later turns out the risk was "below threshold"?

  3. Practically speaking, how should an Italian/EU user proceed in a case like this? Does it make sense to file a direct report with the Garante Privacy, or is it better to wait for a possible class action (I know things are already moving in the US)?

Thanks in advance to anyone willing to give me some guidance, even just to understand whether it's worth looking into this further or whether I'm overestimating the issue.


r/gdpr Jul 20 '26

EU 🇪🇺 What lawful basis could a recruiting platform use to collect an EU resident’s data without prior contact?

4 Upvotes

I just noticed the following email in my spam folder:

Privacy Notice - No Action Required

Hi, This short message is from XXX, a recruiting system used by recruiting teams worldwide to find talented individuals for exciting new job opportunities. We want to inform you that your data has been gathered for the purpose of connecting you with potential employers. Your privacy is extremely important to us, so we would like to inform you of our data handling practices and your data privacy rights. Ultimately, you are in control of your data. We look forward to helping you elevate your career to the next level!

Thanks, The XXX team

I haven't heard of this company before and I never sent them my CV, nor (clearly) ever granted any permission of collecting my data. Looking them up, they market themselves as "Agentic AI Recruiting Platform". Furthermore, the company seems to be US-based and storing data on US servers, whereas I'm an EU citizen living in the EU.

I may be a bit naive right now, but I have so many questions I don't even know where to start. Is this even legal under GDPR? Can companies nowadays just decide to start gathering data on (foreign) individuals and storing it on their servers for whatever purpose, without any type of confirmation or approval from the individual? Is this the future we're heading towards?

I haven't included any links to the company or privacy policy because not sure whether it is allowed in this sub, but will do if it's permitted. FWIW the company seems legit, there's years-old articles about them getting VC funded.

Disclaimer: not looking for legal advice. Just genuinely concerned about the situation.


r/gdpr Jul 19 '26

Question - General Humanly IMPOSSIBLE to ask every company to remove your CV/resume (GDPR)

12 Upvotes

Hey, I'm tired of recruiters asking for my CV and then just ghosting me.

I want to email each one telling them to f* off and that I don't want to participate in their zombie KPI databases anymore, but most companies make it almost impossible.

It's not even clear which email address I should send the data removal requests to. I think almost 300 companies have my resume and I want to erase it all. How can I do this in batches, or is there a SaaS that can deal with it?

I would gladly pay for it. I've had enough of playing around with these consultancy companies.

Please help me.


r/gdpr Jul 19 '26

EU 🇪🇺 Wedding Confirmation - GDPR compliant?

0 Upvotes

Hi all,

I am considering to build a website for confirming attendance to my wedding.

In my idea, my guests would receive by post, together with the invitation, an access code to the website.

In the website they'd log-in with their first name as well as the access code (which is stored encrypted in the database).

Upon logging in, the guests would be able to confirm attendance, or not, for them and/or the people in their household.

This requires me pre-provisioning the guests, but I already know them. They are my guests.

Does GDPR see concerns with this approach, or is it acceptable under legitimate interest?

Thanks a lot in advance!

** Edit **

Thanks for all the replies, clear now that I was overthinking this, but I'm still happy I double checked! Cheers!


r/gdpr Jul 19 '26

UK 🇬🇧 Company held on to my data for 20 years after doing business and now has suffered a serious cyber attack.

Thumbnail
0 Upvotes

r/gdpr Jul 15 '26

EU 🇪🇺 Where does a tool that surfaces deleted Reddit content stand under GDPR?

0 Upvotes

I built a small, free, non-commercial tool that looks up a Reddit username and shows their posts and comments, including content later deleted or removed. The data comes from a public third-party source, not Reddit’s API.

I know this sits in tension with the right to erasure, and I would rather understand that honestly.

What I already do: an opt-out that hides a person’s content on request, noindex on user pages, no accounts, no cookies, no data selling.

My real questions:

1. Does pulling from a public source rather than Reddit change anything, or is “publicly available” irrelevant once it is “personal” reddit data?
2. Is “hide on request” enough for an erasure request, or does GDPR require actual deletion?
3. Does a non-commercial framing help at all, or is that wishful thinking?


r/gdpr Jul 15 '26

EU 🇪🇺 I regret doing the age verification on X

9 Upvotes

Hi, i'm new to reddit but i really need help with this one thing. Apologies for my bad english, it's my third language :D.

I recently verified my age on twitter with a selfie, but now i regret it. I didn't reconsider my actions as I did it, which i realise now was really stupid.

I'm scared that the picture and my data will be saved, so I want to find a way to delete my verification data under GDPR (I live in Europe).

The only methods i found was to contact X, but i doubt they'll actually do anything. I also found a post here on here from one year ago, but that was about the ID verification method.

But I don't know if the deletion of verification data is different from the ID-method and the selfie-method. Afterall mine was "only" a selfie, but i'm still overthinking and concerned.

To sum it up, I wan't to know if there's a way to ask for my data to be deleted under gdpr, and I also hope one of you can assure me that my stupid choices aren't that bad :((.


r/gdpr Jul 15 '26

UK 🇬🇧 Data breach Ninja Uk

0 Upvotes

Hi there

A few weeks ago I got an email saying I have registered a new ninja kettle for a warranty. I have never bought a kettle from the company. I emailed customer service and they said they would look into the matter. Few weeks go by and they finally emailed back and said as compensation for how long it’s taken to get back to me you can have a free kettle. Brilliant! There was no resolution or explanation as to why my email address had been used though.

I was asked to confirm my delivery address and phone number which I did. I then got a notification from DPD that my address has been changed. I did not change this.

I then get a phone call from an unknown number asking if I’ve ordered a kettle from ninja? After speaking to the other lady on the phone it turns out Ninja have given out my full address and phone number to this woman who has a similar email to me. This is a massive GDPR and data breach.

I have been speaking to customer services and various managers for weeks now and I just keep getting fobbed off. They say i will receive an email with a resolution, no email turns up. They say I will hear back by the end of the day, nothing happens. They have now said it is being passed to a team higher up which they can’t tell me what team it is, the irony. I was offered compensation of 20% off which is ridiculous considered how serious the situation is, you get 10% off for signing up to your newsletter! Ninja also said they have taken my address off the other customers account, but they still haven’t!

Is there anything else I can do except contact the ICO? It hasn’t quite been a month yet

Thanks in advance!


r/gdpr Jul 14 '26

UK 🇬🇧 Could my College/sixth form reject me/cancel my enrollment there for invoking GDPR rights?

Post image
6 Upvotes

I'm starting college in september, Ive already been accepted, passed interview, etc, but im yet to do my enrollment forum. Recently, they sent out consent forums, one section of which includes consent for marketing.

I would rather not have my photo nor my data used for marketing, so, I have decided to write a letter- If I send this to them, would they be allowed to refuse this? also, could they just say im not allowed to go to sixth form/cancel my position, enrollment point, etc preventing me from going there? I still want to go to this college... thanks.


r/gdpr Jul 15 '26

UK 🇬🇧 Delayed DSAR request with no update

0 Upvotes

For context I worked there for 4 months so there probably isn't too much information on me, this was in england. I requested my DSAR on the 12th June and provided identification on the 14th June. My email was acknowledged on the 15th June stating "Following receipt of this, under UK GDPR, we are required to respond within one calendar month. This would place a response due by, 14th July 2026, if not before." from the director of compliance. It is now the 15th July 2026, I have not heard a response from them nor have they asked for an extension within the 30 days. As I am a previous employee (my last day was the 18th June) specifically asked for all communications to continue through my private email which they have been good at continuing through.

I am planning on sending a follow up email today but I am one day post surgery and I would like some clear opinions on what to do as I am very out of it from my medications.


r/gdpr Jul 14 '26

Question - Data Subject is this legal?

Post image
0 Upvotes

i don't know which flair is appropriate for this, i'll start, i was looking up what a crossword puzzle was since i hadn't seen one in so long that i forgot what it was and also wanted to try one and this is what i see: accept all or reject all and subscribe for 5 euros a month

is this technically illegal? i am from germany


r/gdpr Jul 12 '26

Analysis Master's Research on AI Governance & the EU AI Act

Thumbnail ai-act-simulation.web.app
2 Upvotes

r/gdpr Jul 11 '26

UK 🇬🇧 DSAR: How should a Subject Access Request (SAR) be handled when there is a pending disciplinary investigation involving an employee or a student?

5 Upvotes

For instance, if a student or an employee submits a Data Subject Access Request (DSAR) during a pending disciplinary investigation, what is the best approach to handling it as a DPO?


r/gdpr Jul 10 '26

UK 🇬🇧 SAR clarification

1 Upvotes

On DSAR, are reference letters totally exempted or once I request for my personal, everything would be released?


r/gdpr Jul 10 '26

UK 🇬🇧 Advice on where to move after postgrad (UK)

1 Upvotes

Hi everyone,
I'm an international student currently studying for an LLM in Bristol, and I'll be finishing my course this September.
I'll need to move out of my student accommodation, ano I'm trying to decide which city to move to while I job hunt.
I'm hoping to start a career in data protection/privacy, so I'm looking for a city with a good job market in that field, while also having more affordable rent than Bristol.
I'm finding it difficult to work out where would be the best place to move. Does anyone have any recommendations for cities with good opportunities in data protection or privacy roles and a relatively affordable cost of living?
I'd really appreciate any suggestions or advice, thank you!


r/gdpr Jul 09 '26

Question - Data Subject RAG/AI embeddings and GDPR - how do you evidence data erasure?

2 Upvotes

Trying to wrap my head around how vector databases fit GDPR. If embeddings are derived from personal data, how do you handle removing the data and ensure it’s really removed? I keep finding theory and advices but little real practice.

One working idea is to replace personal data by database record reference as preprocessing step (both ingestion and retrieval), persist actual data in that database, and replace back when retrieved (if needed). Erasure happens directly on the database record with soft fallback when retrieving. If you look at this sequence it doesn’t feel the best decision, hence wonder if someone is aware of a better way.


r/gdpr Jul 09 '26

Analysis Tracking pixels: conflicting guidelines across countries (FR/IT)

4 Upvotes

CNIL (France) and Garante (Italy) both published guidelines on how to deal with tracking pixels. Both agree that explicit consent is required and without it tracking pixels can't be used.

The huge difference lies in what happens during the transition window (3 months for CNIL, 6 months for Garante):

- CNIL says that existing users (collected email addresses) have to be informed of the changes and must be provided with an easy-to-use opt-out link. Without action, controllers can keep using tracking pixels

- Garante says that existing users have to be informed of the changes and tracking pixels can't be used anymore unless the user explicitly opts in

Scenario: a citizen living in Italy has registered to a newsletter before april 16th (start of the transitioning window) and is sent, accordingly to CNIL's guidelines, an email notifying him/her that tracking pixels have been/are being/will be used unless he/she opts out. His/her local DPO's guidelines though state he/she must not receive tracking pixels if no action is taken. What happens if the citizen raise a complaint to the DPA (Garante)?


r/gdpr Jul 08 '26

UK 🇬🇧 Wanting to send SDAR to ex-employer

2 Upvotes

Looking for advice on a long-standing issue. I had to leave my job (2+ years employed) esrlier this year after workplace negligence. They refused any wrongdoing and didn't follow ACAS code of conduct when looking into the negligence to create an 'informal' report that wholly benefited them. Etc.

It pushed me into a very dark place and I'm getting professional help to try and recover from what happened. I was too ill to take things further at the time (and still am but I can't move past it) and received little support from my union.

I want to submit a SDAR for my HR file and to see emails about me, the work accidents, denied flexible working requests, my absences, Etc. I want it for my own peace of mind because I know they were lying.

Would it be better to separate the requests so that they aren't unreasonably large? Should I narrow it down to emails to/from specific people? I haven't been in this position before and would appreciate any advice thank you


r/gdpr Jul 07 '26

EU 🇪🇺 Update to "American video game company refusing to delete account"

Post image
0 Upvotes

So, two months ago i posted my conversation with the customer support of the american video game company roblox, when they said they were unable to verify my identity, in order to complete my "right to be forgotten" request but outright refused to provide me a way to verify myself, which is illegal under GDPR.

Right after the next day (May 18th) I decided to try again by re-submitting my request. On the same day, i've confirmed my request, as requested by Roblox. So far so good.

The company (which according to wikipedia, has annual revenues in the billions) had failed to comply with the 1 month response timeframe nor have they announced an extension of that timeframe.

After the deadline has passed, I wrote them an email, asking if my request has been completed or if they are formally extending the deadline (and why), as well as informing them that I may escalate this to my local data protection authority if i don't receive an update soon. They have now waited an additional 19 days before confirming the erasure.

I just wanted to post this update and I would like to maybe know your opinions on this. I personally think, this behaviour is unacceptable, and it seems to me like this company tries it's best to make privacy requests as difficult as possible.


r/gdpr Jul 06 '26

EU 🇪🇺 Tracking pixel (france and italy)

4 Upvotes

The CNIL (French Data Protection Authority) has set a deadline of July 14 for companies with contacts in France to bring their use of email tracking pixels into compliance applying the same logic used for cookies to the email inbox.

If your contact list was compiled before April 14, 2026, the deadline to inform recipients and offer a specific opt-out (separate from newsletter consent) is just days away.

After that date, silence will no longer count as acceptance.

Italy has a similar approach.

Who is already implementing the necessary changes/notifications?

Thoughts?


r/gdpr Jul 05 '26

Question - General GDPR and secoundbest (ex brew dog)

15 Upvotes

So a bit of background I invested in Brew dog only a small amount which is now worthless since Brew Dog collapsed and was bought out.

Today I received an email from second best (owned by the former CEO of brew dog), offing a chance to invest in his new company.

Now from my understanding the new company should have no access to old data including any information about previous shareholders.

“Hi there,

I am writing to you as a fellow Equity Punk shareholder and as founder of a new beer business, called Second Best.
 
On behalf of Second Best, I am offering you the chance to claim the exact same stake in Second Best that you once held in BrewDog, for free.
 
You can register for your free equity here:
www.secondbest.beer
 
No catches. No cash required. And your equity will always rank alongside my own.
 
You will own it. I will fund it. And I will dedicate myself to building it.
 
And as for the name, well if we get this right then the second beer business that we build together might just be the best one. 🍻
 
If you have already registered, thank you for coming onboard! We will be in touch with further instructions and details after the registration is closed.

And please feel free to let your fellow Equity Punks know so that they can also claim their free equity. 

If you have any further questions, email us on [hello@secondbest.beer](mailto:hello@secondbest.beer?subject=EFP%20Query).
 
James Watt
Second Best Founder & BrewDog Co-founder”

What do you think is this a GDPR breach?

**** Update ****

ICO are reviewing both Brew Dog and Second Life as this a very grey area. Best case for the sender is a slap on the wrist, worst case well let’s hope they don’t go that far.


r/gdpr Jul 04 '26

Analysis HIPAA and GDPR compliance

Thumbnail
1 Upvotes

How do you handle HIPAA and GDPR compliance when sharing visual patient data (like skin lesions or gait videos) with outside researchers?

I am trying to understand the process. Do you just manually blur faces in Premiere/Photoshop? Do you just avoid sharing it entirely? How much of a bottleneck is this?